A heap-based buffer overflow vulnerability has been identified in Open5GS version 2.8.0, specifically within the function hss_ogs_diam_s6a_air_cb located in src/hss/hss-s6a-path.c. The vulnerability resides in the S6a Authentication-Information-Request Handler component and can be triggered by manipulating the Visited-PLMN-Id argument. The flaw allows remote attackers to exploit the overflow without requiring local access. Open5GS is an open-source implementation of 5G and LTE core network components, making this vulnerability particularly significant for telecommunications infrastructure. A patch has been identified (commit a9c82ee0b590d76a581b0580cb46b598984e2392) and is available on the official GitHub repository. Administrators running Open5GS 2.8.0 are strongly advised to apply the patch immediately to mitigate potential exploitation. The vulnerability has been tracked and disclosed via NVD and VulDB databases.